<?php

class EprofModel extends Model {
	function update($field){
		//mkdir("img/".$field['username'],0777);
		
		//save uploaded file
		if ($field["pp"]["error"] > 0){
			//do nothing
		}else{
			if (file_exists("img/" .$field['username'].'/'.$field["pp"]["name"])) {
				//echo $field["pp"]["name"] . " already exists. ";
                                $pict_url = "img/" .$field['username'].'/'. $field["pp"]["name"];
			}
			else{
				move_uploaded_file($field["pp"]["tmp_name"],"img/" .$field['username'].'/'. $field["pp"]["name"]);
				$pict_url = "img/" .$field['username'].'/'. $field["pp"]["name"];
			}
		}
		
		//do the query
		//$insert_string = "'".$field['fullname']."','".$field['password']."','".$field['tgllahir']."','".$field['email']."','".$pict_url."',".$field['gender'].",'".$field['kota']."'";
                $s1 = "'".$field['username']."'";
                $s2 = "'".$field['password']."'";
                $s3 = "'".$field['tgllahir']."'";
                $s4 = "'".$field['email']."'";
                $s5 = "'".$field['gender']."'";
                $s6 = "'".$field['kota']."'";
                $s7 = "'".$field['fullname']."'";
                $s8 = "'".$pict_url."'";
                $this->query('update user set Fullname = '.$s7.', password = '.$s2.', tgllahir = '.$s3.', email = '.$s4.', pp = '.$s8.', gender = '.$s5.', kota = '.$s6.' where username = '.$s1.'');
                
	}
}
